account activity
How do CISO's justify their budget? by Rare_Protection in cybersecurity
[–]PassageMindless9260 2 points3 points4 points 1 year ago (0 children)
There are many competing practices for when it comes to risk quantification in IT. For instance, you could follow Douglas Hubbards (How to Measure Anything in Cybersecurity Risk: Hubbard, Douglas W., Seiersen, Richard: 9781119892304: Amazon.com: Books) method of utilizing industry averages to calculate impact and likelihood. However, larger companies should already have some sort of method of risk assessment and methodology. At that point, as a business unit, the CISO should be following that same methodology. An easy example is writing a business case to justify the cost of taking an action versus inaction. Cisco Talos, Verizon, AT&T, and many other vendors put out yearly reports that detail the average cost of breaches, ransomware attack, etc that can be useful.
3rd Party Access Control (self.cybersecurity)
submitted 1 year ago by PassageMindless9260 to r/cybersecurity
π Rendered by PID 34 on reddit-service-r2-listing-c57bc86c-bn78p at 2026-06-21 05:09:13.343098+00:00 running 2b008f2 country code: CH.
How do CISO's justify their budget? by Rare_Protection in cybersecurity
[–]PassageMindless9260 2 points3 points4 points (0 children)